domain-entities-review

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands including ls, rg (grep), and git diff to discover project configuration and search for design patterns within the local filesystem.
  • [COMMAND_EXECUTION]: It executes a project-local Python script (.claude/scripts/code_graph) to perform dependency tracing and code graph analysis.
  • [COMMAND_EXECUTION]: The skill is authorized to invoke the spawn_agent capability to parallelize the review process for large changesets, using a structured prompt template to maintain protocol consistency.
  • [PROMPT_INJECTION]: The skill processes project source code as untrusted input, which presents a surface for indirect prompt injection. This risk is mitigated by requiring mandatory file:line evidence for every finding and a terminal validation gate ($why-review) that adversarialy tests findings before they are finalized.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — domain-entities-review